Executive brief
LocalGov Workflows is a Drupal module used by local government websites to manage content approvals and scheduling. A security flaw allows unauthorized users to view sensitive information, including the names of service contacts and the specific content items assigned to them. This could lead to the exposure of internal staff details and organizational workflows to the public.
Technical details
A missing authorization vulnerability (CWE-862) exists in the LocalGov Workflows module for Drupal. The module fails to sufficiently restrict access to a specific view of 'Service Contacts,' which allows an unauthenticated attacker to perform 'forceful browsing' to access the page. Successful exploitation results in the disclosure of service contact names and the content items associated with them. The issue is fixed in version 1.6.0.
Affected products
- Drupal LocalGov Workflows 0.0.0 to 1.6.0
Timeline
- 2026-06-03: patched: Version 1.6.0 released to address the vulnerability.
- 2026-06-03: advisory: Drupal security advisory SA-CONTRIB-2026-039 published.
- 2026-07-10: disclosed: CVE-2026-10768 published.